Ximing Chen 0004

dblp:158/5173-4 · DBLP profile ↗
← Back
3ranked-venue papers
1as first author
3since 2021 · last 2026
0000-0002-7238-9620ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 1 first-author · 3 since 2021
YearPublicationVenuePosition
2026 DynAssetRank: Real-Time Dynamic Risk Assessment for Network Threat Prediction With ATT&CK Modeling
Ximing Chen 0004, Xilong He, Lichen Nong, Jing Qiu 0002, Du Cheng, Lejun Zhang, Lihua Yin
IEEE Trans. Dependable Secur. Comput.1
2026 Large-Scale Intranet Security Assessment Based on Bayesian Attack Graphs Using System Audit Logs
abstract
Large-scale dynamic intranet environments are characterized by constantly changing configurations, evolving user behaviors, and diverse assets that increase vulnerability pathways. These factors undermine the effectiveness of Bayesian attack graphs and reveal the limitations of traditional security methods that rely on static assumptions. To address these challenges, this paper proposes a novel Bayesian attack graph method designed for large-scale, active intranet security assessments. It captures real-time intranet changes by extracting system audit logs and generates attack graphs with MulVAL, ultimately resulting in a time-spanning understanding of potential security risks. Furthermore, it identifies direct-risk paths by eliminating weak dependencies between actions and estimates the likelihood of action execution based on expectations, thereby substantially reducing the computational complexity of Bayesian security analysis. To validate the proposed method, this paper conducts dynamic threat modeling and quantitative security analysis on an enterprise intranet using logs from over 1,000 hosts. The results demonstrate that the proposed method not only provides internal network security risk values at any given time but also identifies specific and observable potential attack paths. Furthermore, this study provides a reference framework for prioritizing vulnerability remediation based on changes in internal network security conditions
Chengliang Gao, Jing Qiu 0002, Jiaxu Xing, Ximing Chen 0004, Du Cheng, Lejun Zhang, Tiejun Wu
IEEE Trans. Dependable Secur. Comput.4
2025 MalFSCIL: A Few-Shot Class-Incremental Learning Approach for Malware Detection
abstract
The continuous evolution of malware is posing a serious threat to personal privacy, enterprise data security, and global network infrastructure. For example, attackers can use phishing emails, botnets, etc. to induce victims to execute malware for nefarious purposes such as stealing sensitive information. Therefore, it is significant to develop effective and efficient methods to detect malware. Towards this, most state-of-the-art methods are focused on learning-based method. In order to adapt to the characteristics of sample scarcity and dynamic evolution of malware detection tasks, few-shot class incremental learning has been proposed as an efficient pairwise solution. Nevertheless, they still face two major challenges: 1) Catastrophic Forgetting: the erosion of existing knowledge by newly acquired knowledge during incremental learning. 2) Decision boundary confusion: after continuous multiple incremental sessions, the discriminative ability of the classification model is weakened. To address the above challenges, we propose a new Malware detection framework based on Few-Shot Class Incremental Learning, MalFSCIL, which utilizes a decoupled training strategy combined with a variational autocoder to mitigate catastrophic forgetting, and designs a dynamic boundary delineation method based on class prototyping to achieve accurate delineation of incremental decision boundaries. Extensive experimental results show that the proposed method outperforms the state-of-the-art techniques in malware detection and classification with high classification accuracy with open-source dataset and Internal enterprise dataset.
Yuhan Chai, Ximing Chen 0004, Jing Qiu 0002, Yanjun Xiao 0001, Qiying Feng, Shouling Ji, Zhihong Tian 0001
IEEE Trans. Inf. Forensics Secur.2